From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f80.google.com (mail-oo1-f80.google.com [209.85.161.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B69B349CFD for ; Thu, 21 May 2026 15:27:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.80 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779377261; cv=none; b=Cck5W7n2jwmz3Xc+MEOZoflxbXFsia9/86GHP12a/x7hUMvhXhYbANeN28Lj8ATDGdvllWVCxOeAgJHdNQ5iasMtP7pg20yRcIk35l3OWi6VzH56qpPnuySNBqyj0Cnq/HS2PcyXFx/nFe9Ylo6zjF7bY+WG3fn4PzCEMTpvOYY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779377261; c=relaxed/simple; bh=YMyWGhnn82d8s1VoNMYdEELPpWZHkibRtHoYKpx5irw=; h=MIME-Version:Date:Message-ID:Subject:From:To:Content-Type; b=Qi2+faSYRZF3bgoRcfvhTtYq4yPY14lxKx3CmE0FN6EevXU8xGRxgMZi2upIjca5ej+oZKJNjqn4Pm6ksjuc9Q0aKpSZXXvsKhDXcZl8FozHsA9Nep2+TJeMZkcfli9KpwZGVQmOhaeSaMG2SYXUM2MQvwmtWpygGRWMWrVGork= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.161.80 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oo1-f80.google.com with SMTP id 006d021491bc7-69d77736830so1115984eaf.3 for ; Thu, 21 May 2026 08:27:40 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779377259; x=1779982059; h=to:from:subject:message-id:date:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=Q7+Keg766WhyWy3D295hfJ9yyxOp545yG2+nUaggzYc=; b=rpPyVD/CcRYoWMCO2byKQSOjSlXCmRykH6DwEBHigqY9TWh1qlgNHA3RapxhmHGYBa gPQirKrNtH9/cmde76go6UbkLrHWo2Fnvn4ToTUQrNeYmZ5HwNdoKo+gjAGQuHIBhPYO hBFHh/HuQbHQFh/jfTFrC61qvLU+NA/6ZQlAJ7HjA/pZhLUIk2EfOkWnx8/ZbgZQDCW1 gUu7f4tJQTD0MjNYXXJ7eO+YtGTFw/tMMvrZNyFX3hZlbk/WHo6rlS2oF2mrElrpw+cP 1+A09u9XfsELPENYPY+CmOe2OtQjJqBzsv7DG7AOuae7g6kpENw2JUdQlh5AvgBKQ1RP x2uA== X-Forwarded-Encrypted: i=1; AFNElJ8kgjnqwsz4L4wZMZYDNv2+03ktAWN9CbAiB+FvOxGX6rhh3KOQ8v3yjc13TI/sV/aA5hvRL44=@vger.kernel.org X-Gm-Message-State: AOJu0YyLkjH5f4UfRJan1TmBbWB5nXa3YM36aM/1jte05d4K9soPIRhA 7a4muYGg8klM8HJIciG9vUc84agais5Oas2fjrdxj/MLUbVQabEzGRST/k0kwG5QwoylYbhVBLQ V0vj93qVZUMO0E0feBPhZ7MumVD508cK7Rod6JkqjPaxQe3sYSMqR0rQI+Iw= Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6820:4b0f:b0:695:b571:e574 with SMTP id 006d021491bc7-69d6ef88c3amr1658944eaf.59.1779377259512; Thu, 21 May 2026 08:27:39 -0700 (PDT) Date: Thu, 21 May 2026 08:27:39 -0700 X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a0f246b.170a0220.303405.4ce3.GAE@google.com> Subject: [syzbot] [wireless?] WARNING in drv_get_tsf (3) From: syzbot To: johannes@sipsolutions.net, linux-kernel@vger.kernel.org, linux-wireless@vger.kernel.org, netdev@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Hello, syzbot found the following issue on: HEAD commit: 6916d5703ddf Merge tag 'drm-fixes-2026-05-16' of https://g.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=14dd2536580000 kernel config: https://syzkaller.appspot.com/x/.config?x=d0f0911eedbc130a dashboard link: https://syzkaller.appspot.com/bug?extid=1c8c45017f784e646b47 compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image: https://storage.googleapis.com/syzbot-assets/1efefe7c73e1/disk-6916d570.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/1dcf16f12a0f/vmlinux-6916d570.xz kernel image: https://storage.googleapis.com/syzbot-assets/7bc2e1f3e5cd/bzImage-6916d570.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: syzbot+1c8c45017f784e646b47@syzkaller.appspotmail.com ------------[ cut here ]------------ wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:255 at drv_get_tsf+0x33f/0x770 net/mac80211/driver-ops.c:255, CPU#0: kworker/u8:17/7122 Modules linked in: CPU: 0 UID: 0 PID: 7122 Comm: kworker/u8:17 Tainted: G L syzkaller #0 PREEMPT(full) Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 Workqueue: events_unbound cfg80211_wiphy_work RIP: 0010:drv_get_tsf+0x345/0x770 net/mac80211/driver-ops.c:255 Code: 0a 00 00 4d 85 ed 0f 84 45 03 00 00 e8 34 92 11 f7 49 81 c5 20 01 00 00 e8 28 92 11 f7 48 8d 3d c1 57 f2 05 44 89 f2 4c 89 ee <67> 48 0f b9 3a e9 a6 fd ff ff e8 0c 92 11 f7 65 44 8b 25 78 47 14 RSP: 0018:ffffc90003797b70 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88805c850e40 RCX: ffffffff8af67847 RDX: 0000000000000000 RSI: ffff88805c850120 RDI: ffffffff90e8d060 RBP: ffff88805c830f20 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff88805c851878 R13: ffff88805c850120 R14: 0000000000000000 R15: ffff88805c8306c0 FS: 0000000000000000(0000) GS:ffff888124374000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f619fa17e9c CR3: 000000005f5f6000 CR4: 00000000003526f0 Call Trace: ieee80211_if_fmt_tsf+0x42/0x70 net/mac80211/debugfs_netdev.c:660 wiphy_locked_debugfs_read_work+0xe6/0x1c0 net/wireless/debugfs.c:168 cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513 process_one_work+0xa0e/0x1980 kernel/workqueue.c:3314 process_scheduled_works kernel/workqueue.c:3397 [inline] worker_thread+0x5ef/0xe50 kernel/workqueue.c:3478 kthread+0x370/0x450 kernel/kthread.c:436 ret_from_fork+0x72b/0xd50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 ---------------- Code disassembly (best guess): 0: 0a 00 or (%rax),%al 2: 00 4d 85 add %cl,-0x7b(%rbp) 5: ed in (%dx),%eax 6: 0f 84 45 03 00 00 je 0x351 c: e8 34 92 11 f7 call 0xf7119245 11: 49 81 c5 20 01 00 00 add $0x120,%r13 18: e8 28 92 11 f7 call 0xf7119245 1d: 48 8d 3d c1 57 f2 05 lea 0x5f257c1(%rip),%rdi # 0x5f257e5 24: 44 89 f2 mov %r14d,%edx 27: 4c 89 ee mov %r13,%rsi * 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction 2f: e9 a6 fd ff ff jmp 0xfffffdda 34: e8 0c 92 11 f7 call 0xf7119245 39: 65 gs 3a: 44 rex.R 3b: 8b .byte 0x8b 3c: 25 .byte 0x25 3d: 78 47 js 0x86 3f: 14 .byte 0x14 --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at syzkaller@googlegroups.com. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup